Junglewise Threat Intelligence

CVE-2026-14685: HdrHistogram state manipulation in recordValueWithCount

CVE-2026-14685 · Severity: low · CVSS 3.3 · Published 2026-07-05

Technologies: HdrHistogram. Vendors: HdrHistogram.

Executive brief

HdrHistogram is a Java library used by developers to track and analyze the distribution of values, such as application latency. A flaw in the library allows a local user to provide negative count values, which can corrupt the internal state of the histogram. This could lead to incorrect data reporting or unexpected behavior in applications that rely on this library for performance monitoring.

Technical details

A state manipulation vulnerability (CWE-371) exists in HdrHistogram versions up to 2.2.2 within the recordValueWithCount function of AbstractHistogram.java. The root cause is the lack of validation for the 'count' argument, which allows the function to accept negative values. An attacker with local access to the environment where the library is running can exploit this to manipulate the internal state of the histogram. While the impact is limited to integrity (incorrect data state), the exploit has been disclosed publicly. As of the advisory date, the project maintainers have not yet released a patch.

Affected products

  • HdrHistogram HdrHistogram Up to 2.2.2

Timeline

  • 2026-07-05: advisory: NVD publication date
  • 2026-07-05: disclosed: Public disclosure of the exploit

References

Related threats